Re: One-Time passwords for regular user accounts?



Carlos Moreno <moreno_at_mochima_dot_com@xxxxxxxxxxxxxx> writes:

John Thompson wrote:

I wonder if there is a way (a standard way, that is) to setup
one-time passwords for logging in to a Linux box (through SSH).

Search google on "opie" (one-time passwords in everything) and "S/KEY"

Hmmm... The information seems a bit scarce. But still, from one of
the descriptions I read, it seems to be resistant to sniffing attacks,
and not to key loggers. But using SSH -- which I do -- makes me
already impervious to sniffing.


No, it is also resistant to key loggers.
The key is never reused, so who cares if they got the current key. It will
never again work.

My concern is that I do not trust the keyboard where I'm typing my
password -- that's why I would like the server to have a list of
passwords ready to use, and as soon as one of them is used, it is
immediately removed from that list.

Precisely what Opie does, it ia more subtle and orgnaized fashion.



Am I getting it wrong?

You are getting opie wrong.
.



Relevant Pages

  • Re: One-Time passwords for regular user accounts?
    ... one-time passwords for logging in to a Linux box (through SSH). ... the descriptions I read, it seems to be resistant to sniffing attacks, ...
    (comp.os.linux.setup)
  • Re: OPIE considered insecure
    ... Enhance OPIE to use larger internal hashes. ... the algorithm won't be brute-forced ... of one time passwords that can be generated is unlimited. ... The one time passwords should definitively be independent from each other; ...
    (FreeBSD-Security)
  • Re: One-Time passwords for regular user accounts?
    ... one-time passwords for logging in to a Linux box. ... Opie is a one time challenge response system. ... It could be susceptible to active attacks, ...
    (comp.os.linux.setup)
  • Re: telnet replacement - not ssh?
    ... Note the cautionary note at the end of the abstract: ... Passwords In Everything) Software Distribution is an enhancement ... OPIE can be an important part of one. ... preserve the confidentiality or integrity of the data in the stream. ...
    (comp.security.ssh)
  • Re: telnet replacement - not ssh?
    ... Note the cautionary note at the end of the abstract: ... Passwords In Everything) Software Distribution is an enhancement ... OPIE can be an important part of one. ... preserve the confidentiality or integrity of the data in the stream. ...
    (comp.security.unix)